Back to Latest
News May 19, 2026

UK Plan for Mandatory Online Age Checks Prompts Privacy and Security Fears

The British government is considering legislation that would expand age verification requirements across the internet, potentially imposing curfews and access limits for younger users and new checks on services from games to VPNs and websites. Critics warn the plan would require broad proof-of-age measures for all users, weaken anonymity, create a fractured web of age-restricted zones and introduce major security risks if verification data were exposed.

By Charles Oliver 697 views
UK Plan for Mandatory Online Age Checks Prompts Privacy and Security Fears
The British government is weighing a proposal that would expand age-verification requirements across a wide range of online services, a plan that could lead to internet curfews for younger users and significant new obligations for adults as well. The proposals build on the Online Safety Act 2023, under which age checks for pornography and content related to suicide, self-harm and eating disorders already took effect in July 2025, typically enforced through ID uploads, facial-age scans, or third-party verification services such as Yoti. The new measures are being advanced on two tracks: a government consultation, launched in early 2026 and scheduled to close on May 26, and a set of amendments to the Children's Wellbeing and Schools Bill that the House of Lords has voted to attach, including a requirement that platforms adopt "effective age assurance" to keep under-16s off social media within twelve months and a separate provision extending age checks to virtual private networks (VPNs) to prevent children from using them to evade the rules. Ministers have signaled they intend to move quickly, and the education secretary has indicated the government will impose some form of age or functionality restriction even if it stops short of a full under-16 ban. Beyond a possible minimum age for social media, the consultation floats overnight curfews, mandatory usage breaks to curb "doom-scrolling," limits on addictive design features such as infinite scroll and streaks, and raising the digital age of consent from 13 to 16.
Critics warn that the breadth of the plan would have consequences well beyond children. Because platforms cannot tell minors from adults without checking everyone, digital-rights groups argue the measures would in practice require an estimated 55 million British adults to submit identity documents or biometric data simply to use ordinary services, eroding online anonymity and building what some describe as a mass-surveillance infrastructure. The proposed VPN checks have drawn particular criticism, since VPNs are legitimate privacy and security tools relied on by businesses, journalists and travelers, and requiring users to identify themselves to access one is seen as undercutting the very purpose of the technology. Opponents also caution that the scope could sweep in messaging apps, online games with social features, and reference sites, fracturing the web into a patchwork of age-gated zones, and they note that the original Online Safety Act required verification to be robust without imposing detailed duties on how the resulting trove of sensitive data must be protected — raising the prospect of serious harm if verification records were breached or leaked.
Supporters of the government's approach maintain that stronger protections are necessary to shield children from online abuse, exploitation and exposure to inappropriate content. Advocates for the measures contend that without reliable ways to distinguish minors from adults, platforms will struggle to effectively enforce age-appropriate safeguards. They point to Australia, which brought its own under-16 social media ban into force in December 2025 and reported millions of accounts removed, as evidence that enforcement is feasible even if imperfect. In their view, carefully designed verification systems could reduce risks to children while enabling compliant adults to continue using services normally.
The debate highlights a broader tension in digital policy between safeguarding vulnerable populations and preserving civil liberties. Policymakers must weigh the potential benefits of more rigorous age checks against the privacy and security costs critics have outlined. How the government chooses to proceed — including what technical methods it would allow for age verification and what safeguards it would impose on data collection, storage and breach response — will determine whether the final law leans toward child protection or toward restricting online freedoms.
As discussions continue, technology companies, advocacy groups and civil liberties defenders are likely to press for clear limits on data retention, strong security requirements and narrow scopes of enforcement to reduce collateral harm. Meanwhile, proponents of the proposal will emphasize the urgency of updating rules to reflect contemporary online risks to children. The outcome will shape the practical experience of millions of internet users in the United Kingdom and could influence conversations about online age verification in other countries, where governments from Australia to the United States have begun pursuing comparable measures.

SHARE THIS ARTICLE